Beyond SSO: Mobile Money Authentication for Inclusive e-Government in Sub-Saharan Africa

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Adewusi, Oluwole, Msagusa, Wallace S., Imanirumva, Jean Pierre, Obadofin, Okemawo, Ndibwile, Jema D.
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866908557093371904
author Adewusi, Oluwole
Msagusa, Wallace S.
Imanirumva, Jean Pierre
Obadofin, Okemawo
Ndibwile, Jema D.
author_facet Adewusi, Oluwole
Msagusa, Wallace S.
Imanirumva, Jean Pierre
Obadofin, Okemawo
Ndibwile, Jema D.
contents The rapid adoption of Mobile Money Services (MMS) in Sub-Saharan Africa (SSA) offers a viable path to improve e-Government service accessibility in the face of persistent low internet penetration. However, existing Mobile Money Authentication (MMA) methods face critical limitations, including susceptibility to SIM swapping, weak session protection, and poor scalability during peak demand. This study introduces a hybrid MMA framework that combines Unstructured Supplementary Service Data (USSD)-based multi-factor authentication with secure session management via cryptographically bound JSON Web Tokens (JWT). Unlike traditional MMA systems that rely solely on SIM-PIN verification or smartphone-dependent biometrics, our design implements a three-factor authentication model; SIM verification, PIN entry, and session token binding, tailored for resource-constrained environments. Simulations and comparative analysis against OAuth-based Single Sign-On (SSO) methods reveal a 45% faster authentication time (8 seconds vs. 12 to 15 seconds), 15% higher success under poor network conditions (95% vs. 80%), and increased resistance to phishing and brute-force attacks. Penetration testing and threat modeling further demonstrate a substantial reduction in vulnerability exposure compared to conventional approaches. The primary contributions of this work are: (1) a hybrid authentication protocol that ensures offline accessibility and secure session continuity; (2) a tailored security framework addressing threats like SIM swapping and social engineering in SSA; and (3) demonstrated scalability for thousands of users with reduced infrastructure overhead. The proposed approach advances secure digital inclusion in SSA and other regions with similar constraints.
format Preprint
id arxiv_https___arxiv_org_abs_2509_20592
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Beyond SSO: Mobile Money Authentication for Inclusive e-Government in Sub-Saharan Africa
Adewusi, Oluwole
Msagusa, Wallace S.
Imanirumva, Jean Pierre
Obadofin, Okemawo
Ndibwile, Jema D.
Cryptography and Security
Human-Computer Interaction
The rapid adoption of Mobile Money Services (MMS) in Sub-Saharan Africa (SSA) offers a viable path to improve e-Government service accessibility in the face of persistent low internet penetration. However, existing Mobile Money Authentication (MMA) methods face critical limitations, including susceptibility to SIM swapping, weak session protection, and poor scalability during peak demand. This study introduces a hybrid MMA framework that combines Unstructured Supplementary Service Data (USSD)-based multi-factor authentication with secure session management via cryptographically bound JSON Web Tokens (JWT). Unlike traditional MMA systems that rely solely on SIM-PIN verification or smartphone-dependent biometrics, our design implements a three-factor authentication model; SIM verification, PIN entry, and session token binding, tailored for resource-constrained environments. Simulations and comparative analysis against OAuth-based Single Sign-On (SSO) methods reveal a 45% faster authentication time (8 seconds vs. 12 to 15 seconds), 15% higher success under poor network conditions (95% vs. 80%), and increased resistance to phishing and brute-force attacks. Penetration testing and threat modeling further demonstrate a substantial reduction in vulnerability exposure compared to conventional approaches. The primary contributions of this work are: (1) a hybrid authentication protocol that ensures offline accessibility and secure session continuity; (2) a tailored security framework addressing threats like SIM swapping and social engineering in SSA; and (3) demonstrated scalability for thousands of users with reduced infrastructure overhead. The proposed approach advances secure digital inclusion in SSA and other regions with similar constraints.
title Beyond SSO: Mobile Money Authentication for Inclusive e-Government in Sub-Saharan Africa
topic Cryptography and Security
Human-Computer Interaction
url https://arxiv.org/abs/2509.20592